Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2014-2066
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving th…
Jenkins
after 1.550
HIGH 9.3
CVE-2014-2927EPSS 8%
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …
Arx
No fix yet
HIGH 7.5
CVE-2014-6379
Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X…
Junos
Mitigation only
MEDIUM 5.0
CVE-2014-3402
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection …
Intrusion Prevention System
after 7.0
HIGH 7.5
CVE-2014-6632
Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions…
Joomla\!
Mitigation only
MEDIUM 5.0
CVE-2014-5300EPSS 7%
Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execu…
Moab
after 7.2.8
HIGH 7.5
CVE-2014-0074EPSS 5%
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…
Shiro
No fix yet
HIGH 8.3
CVE-2013-3092
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation o…
N300 Firmware
No fix yet
MEDIUM 5.0
CVE-2014-3106
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protec…
Rational Clearcase
Patch available
MEDIUM 5.0
CVE-2014-3101
The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a…
Rational Clearcase
Patch available
MEDIUM 5.0
CVE-2014-5412
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…
Clearscada
Mitigation only
HIGH 7.5
CVE-2014-2685
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 v…
Zend Framework
after 2.0.1
HIGH 9.3
CVE-2014-4619
EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manag…
Rsa Identity Management And Governance
No fix yet
MEDIUM 6.0
CVE-2014-0482
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release c…
Django
after 1.4.13
HIGH 7.2
CVE-2014-4325
The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contri…
Little Kernel Bootloader
Patch available
HIGH 7.2
CVE-2014-0973
The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center …
Little Kernel Bootloader
Patch available
MEDIUM 5.0
CVE-2014-5385
com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which make…
Shopizer
after 1.1.5
HIGH 7.5
CVE-2014-5175
The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve…
Solution Manager
Mitigation only
MEDIUM 6.4
CVE-2014-3895
The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 an…
Ts Wlcam\/v Camera Firmware
after 1.08
MEDIUM 6.0
CVE-2014-3552
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not chec…
Moodle
after 2.3.11
HIGH 7.5
CVE-2014-4725EPSS 60%
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrar…
Mailpoet Newsletters
after 2.6.6
HIGH 10.0
CVE-2014-2955
Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher s…
Px
after 1.5.8
HIGH 7.5
CVE-2013-6117EPSS 70%
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials,…
Dvr Firmware
No fix yet
MEDIUM 6.9
CVE-2014-3312
The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex…
Spa 301 1 Line Ip Phone
Mitigation only
HIGH 7.5
CVE-2014-2614
Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown ve…
Sitescope
Mitigation only
MEDIUM 5.0
CVE-2014-4168
(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been …
Iodine
after 0.6.0
MEDIUM 6.8
CVE-2014-4668
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthe…
Fedora
after 1.2.103
MEDIUM 6.8
CVE-2014-2005
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu…
Enterprise Console
after 5.2.1
HIGH 8.0
CVE-2014-3053
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce…
Security Access Manager For Web 8.0 Firmware
Mitigation only
HIGH 10.0
CVE-2014-2609EPSS 13%
The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute ar…
Executive Scorecard
Mitigation only